๐ Security & Compliance
211 tools compared
๐ Subcategories
๐ Audit Management
11 tools
๐ Compliance Management
14 tools
๐ HIPAA Compliance
6 tools
๐ Identity Management
16 tools
๐ Password Management
32 tools
๐ PCI DSS Compliance
5 tools
๐ Risk Management
20 tools
๐ Security Monitoring
20 tools
๐ Security Questionnaires
22 tools
๐ SOC 2 Compliance
20 tools
๐ Vendor Risk Management
25 tools
๐ Vulnerability Scanning
20 tools
๐ง Tools in Security & Compliance
Drata
An AI-native platform to automate compliance, manage risk, and accelerate security reviews.
Rippling
Manage your company's HR, IT, and Finance โ all in one platform.
Nodeware
A continuous vulnerability management solution that is simple, affordable, and effective.
CrowdStrike Falcon
A cloud-native endpoint protection platform.
1Password
A password manager that provides a place for users to store various passwords, software licenses, and other sensitive information.
Burp Suite
A graphical tool for testing Web application security.
Sprinto
A security compliance automation platform for fast-growing tech companies.
SentinelOne
An autonomous endpoint protection platform.
Bitwarden
An open-source password management solution for individuals, teams, and business organizations.
JumpCloud
An open directory platform for identity, access, and device management.
Nmap
A free and open-source utility for network discovery and security auditing.
Scrut Automation
A compliance automation platform for cloud-native companies.
Hunters
An open extended detection and response (XDR) platform.
Passbolt
An open-source password manager designed for collaboration in teams and businesses.
Thales SafeNet Trusted Access
An access management and authentication service from Thales.
Intruder
A proactive vulnerability scanner that finds cybersecurity weaknesses in your digital infrastructure.
AuditBoard
A cloud-based platform to elevate audit, risk, and compliance teams.
Rapid7 InsightIDR
A cloud-native SIEM and XDR solution.
Keeper
A password manager and digital vault that provides a secure and convenient way to protect passwords and private information.
Okta
Securely connect the right people to the right technologies at the right time.
Wireshark
The worldโs foremost and widely-used network protocol analyzer.
Vanta
Automates security and compliance to help businesses get and stay compliant.
Palo Alto Networks Cortex XDR
An extended detection and response (XDR) platform.
RoboForm
A password manager and web form filler that automates password entering.
Duo Security
A cloud-based security platform that protects access to all applications, for any user and device, from anywhere.
sqlmap
An open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws.
Hyperproof
A platform to simplify compliance, risk, and audit management.
Microsoft Sentinel
A cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution.
Delinea Secret Server
A privileged access management (PAM) solution that secures and manages privileged accounts and credentials.
Microsoft Entra ID
A cloud-based identity and access management service from Microsoft.
ConnectSecure
A vulnerability management platform designed for Managed Service Providers (MSPs).
Wazuh
An open-source security platform.
Secureframe
An all-in-one security and compliance automation platform to help businesses get and stay compliant.
Enpass
An offline password manager that gives you the freedom to store your data wherever you want.
CyberArk
Secure access for any identity - human or machine - to any resource.
Lynis
An extensible security audit tool for systems running Linux, macOS, or Unix-based operating systems.
Tugboat Logic
A platform to automate and simplify security assurance and compliance.
CyberArk Workforce Identity
An identity and access management (IAM) solution that provides secure access to applications and resources for all users.
Elastic Security
A unified security solution that combines SIEM, endpoint security, and cloud security.
ManageEngine ADManager Plus
An integrated Active Directory management and reporting solution.
Invicti
A web application security scanner that provides DAST, IAST, and SCA.
KeePass
A free, open-source, and offline password manager for Windows, with ports available for other platforms.
Graylog
A centralized log management platform.
Auth0
A flexible, drop-in solution to add authentication and authorization services to your applications.
OneTrust
A comprehensive platform for privacy, security, and governance.
OWASP ZAP
An open-source web application security scanner.
Varonis
A data security platform that protects data from the inside out.
Dashlane
A password manager and digital wallet application available on macOS, Windows, iOS, and Android.
Ping Identity
Intelligent identity solutions for the enterprise.
Corporater
A platform for governance, performance, risk, and compliance (GPRC).
Doppler
A universal secrets manager that helps developers manage secrets and app configuration across all environments.
Drata
Automates security and compliance to help companies achieve and maintain certifications like SOC 2 and ISO 27001.
Drata
A security and compliance automation platform.
Drata
A security and compliance automation platform that continuously monitors and collects evidence of a company's security controls.
Scytale
A compliance automation platform that combines software with expert guidance to help companies achieve and maintain security certifications.
Drata
An AI-native platform for automating compliance, managing risk, and accelerating security reviews.
Drata
A security and compliance automation platform that continuously monitors and collects evidence of a company's security controls.
Onspring
A no-code GRC and business process automation platform.
Vanta
Automates security and compliance to help businesses get audit-ready in weeks.
Secureframe
Helps companies get and stay compliant with standards like SOC 2, ISO 27001, and HIPAA.
AuditBoard
A cloud-based platform for audit, risk, and compliance management.
Sprinto
An automation platform that helps cloud companies achieve and maintain security compliance.
Scrut Automation
A smart GRC platform that helps cloud-native companies manage risk and maintain compliance.
Thoropass (formerly Laika)
A platform that combines compliance automation software with expert guidance and audits.
anecdotes
A platform that transforms compliance from a manual, disconnected process into a data-driven one.
AuditBoard
A cloud-based platform for audit, risk, and compliance management.
Conveyor
Conveyor helps businesses automate their security reviews and build trust with customers through a self-service trust portal.
SafeBase
SafeBase helps B2B SaaS companies build and maintain customer trust by creating a transparent and accessible security posture.
Sprinto
Sprinto is a compliance automation platform that helps cloud-based companies get and stay compliant with various security frameworks.
Scrut Automation
A compliance automation platform for monitoring and collecting evidence of security controls to ensure audit readiness.
Sprinto
A compliance automation platform designed for cloud-native companies to streamline their security compliance and audit processes.
AuditBoard
A cloud-based platform for audit, risk, and compliance management.
Strike Graph
A compliance automation platform that helps companies design, operate, and measure their security posture to achieve certifications like SOC 2 and ISO 27001.
StandardFusion
A GRC platform that helps organizations manage risk, compliance, and audits in a single, integrated solution.
Compliancy Group
A healthcare compliance management software that simplifies HIPAA, OSHA, and SOC 2 compliance.
Sprinto
A compliance automation platform designed for cloud-native companies to streamline security certifications.
Sprinto
An automation platform for tech companies to achieve and maintain security compliance and pass audits.
Akeyless Vault
A SaaS-based secrets management platform that provides a secure and unified way to manage secrets.
Passwordstate
A self-hosted password manager for teams and enterprises.
AuditBoard
A cloud-based platform for audit, risk, and compliance management.
Workiva
A cloud platform that unifies financial reporting, compliance, risk, and ESG processes.
HashiCorp Vault
An open-source tool for securely accessing secrets.
Pleasant Password Server
A self-hosted password management solution that is compatible with the KeePass client.
Venminder
A SaaS platform for managing the entire lifecycle of vendor relationships.
Panorays
A platform that automates third-party security management.
Black Kite
A platform providing cyber risk ratings and third-party risk intelligence.
Vanta
An automated security and compliance platform.
Whistic
A platform for assessing, publishing, and sharing security profiles.
Vanta
Vanta helps businesses automate their security and compliance, proving their security to customers and partners.
Loopio
Loopio is an AI-powered platform that helps businesses automate their response process for RFPs, RFIs, and security questionnaires.
AuditBoard
AuditBoard is a cloud-based platform for audit, risk, and compliance management.
Scytale
Scytale is a compliance automation platform that helps businesses achieve and maintain compliance with various security frameworks.
Vanta
Automates security and compliance to help businesses build trust with their customers.
Apptega
A platform that helps businesses of all sizes build, manage, and report on their cybersecurity and compliance programs.
Thoropass
An end-to-end compliance automation platform that combines software with an in-house audit team.
Scytale
An AI-powered compliance automation platform that helps organizations manage security and privacy frameworks.
Vanta
A trust management platform that automates security and compliance to help businesses grow.
Vanta
A trust management platform that automates security and compliance to help businesses get audit-ready fast.
LogicGate (Risk Cloud)
A cloud-based platform that helps organizations automate and manage their GRC processes.
Hyperproof
A software platform that helps organizations manage compliance and risk.
Tugboat Logic (by OneTrust)
A security assurance platform that helps companies prepare for audits and respond to security questionnaires.
SecurityScorecard
Provides security ratings to help organizations manage and reduce cybersecurity risk.
LogicGate
A no-code platform for automating and managing GRC and risk processes.
Hyperproof
A platform to manage compliance and risk management work.
Origami Risk
An integrated platform for risk, safety, and compliance.
Drata
A security and compliance automation platform that helps companies streamline their compliance workflows.
Whistic
Whistic is a vendor security platform that helps businesses assess, share, and manage security information.
Panorays
Panorays is a third-party security management platform that helps businesses reduce their third-party security risk.
Hyperproof
Hyperproof is a compliance operations platform that helps businesses manage their compliance programs and build trust with customers.
LogicGate (Risk Cloud)
LogicGate's Risk Cloud is a GRC platform that helps businesses manage their risk and compliance programs.
Secureframe
Secureframe is a security and compliance automation platform that helps businesses get and stay compliant with various frameworks.
Secureframe
An all-in-one platform that helps businesses get and stay compliant with standards like SOC 2, ISO 27001, HIPAA, and PCI DSS.
LogicGate
A no-code platform for governance, risk, and compliance (GRC) that allows businesses to automate and customize their risk and compliance programs.
Mitratech Alyne
A next-generation GRC platform that helps organizations manage risk, compliance, and cybersecurity.
Hyperproof
A compliance operations platform that helps organizations manage their security and compliance programs.
Tugboat Logic
A security assurance platform that helps companies build and manage their InfoSec programs and prepare for audits.
Secureframe
An all-in-one security and compliance automation platform.
Secureframe
An all-in-one platform for security and privacy compliance, powered by automation and AI.
Nikto
An Open Source (GPL) web server scanner.
Trivy
A simple and comprehensive vulnerability scanner for containers and other artifacts.
Keeper Security
A password manager and secure digital vault for businesses and individuals.
AWS Secrets Manager
A secrets management service that helps you protect access to your applications, services, and IT resources.
Google Cloud Secret Manager
A secure and convenient storage system for API keys, passwords, certificates, and other sensitive data.
Azure Key Vault
A cloud service for securely storing and accessing secrets.
Workiva
A cloud platform for reporting and compliance that connects data and teams.
LogicGate (Risk Cloud)
A no-code GRC platform for automating and managing risk and compliance processes.
Exabeam
A security intelligence platform that provides a smarter SIEM.
Tenable Nessus
A widely used vulnerability scanner for identifying vulnerabilities, misconfigurations, and malware on a variety of network devices.
Acunetix
An automated web application security testing tool that helps you find and fix vulnerabilities.
CloudSploit
An open-source tool for scanning cloud environments for security risks.
Tenable Vulnerability Management
A risk-based view of your entire attack surface to identify, investigate, and prioritize vulnerabilities.
NordPass
A password manager from the creators of NordVPN, designed for a secure and simple digital life.
Zoho Vault
A password manager that helps businesses securely store, share, and manage passwords and other sensitive data.
Password Boss
A password manager and digital wallet designed for simplicity and ease of use.
ManageEngine PAM360
A comprehensive privileged access management (PAM) solution that includes password management capabilities.
CyberArk Privileged Access Manager
A comprehensive privileged access management (PAM) solution that helps organizations secure, manage, and monitor privileged access.
BeyondTrust Privileged Password Management
A privileged access management (PAM) solution that provides secure and automated password management.
ZenGRC by Reciprocity
A GRC platform that helps organizations manage risk and compliance with ease.
LogicManager
An enterprise risk management (ERM) software platform.
Tenable
Provides solutions for cyber exposure, helping organizations manage and measure their cyber risk.
BitSight
A security ratings platform for quantifying and mitigating cyber risk.
UpGuard
A platform for third-party risk management and attack surface management.
Prevalent
A comprehensive platform for third-party and supplier risk management.
ProcessUnity
A platform for automating and streamlining third-party risk management and cybersecurity.
RiskRecon
A cybersecurity ratings and continuous monitoring platform.
UpGuard
UpGuard is a cybersecurity platform that helps businesses manage their attack surface, prevent data breaches, and monitor third-party vendor risk.
SecurityScorecard
SecurityScorecard provides cybersecurity ratings that help organizations manage their security risk and the risk of their third-party vendors.
BitSight
BitSight provides security ratings and analytics to help organizations manage their own security performance and reduce third-party risk.
RiskRecon (a Mastercard Company)
RiskRecon provides a third-party cyber risk management platform that helps businesses understand and act on their third-party risks.
Venminder
Venminder is a third-party risk management platform that helps businesses manage the entire lifecycle of their vendor relationships.
Protecht Group
A provider of enterprise risk management (ERM) software and services.
ServiceNow GRC
An integrated risk management solution built on the Now Platform.
OneTrust
A comprehensive platform for privacy, security, and governance.
ServiceNow GRC
Integrates GRC into the ServiceNow platform, providing a unified view of risk and compliance.
LogicManager
An enterprise risk management (ERM) software that helps organizations manage risk and compliance.
Riskonnect
A platform that provides a comprehensive view of risk across the enterprise.
OneTrust
A platform for privacy, security, and governance, including third-party risk management.
ServiceNow Vendor Risk Management
An integrated application for managing vendor risk on the Now Platform.
CyberGRX
A global cyber risk exchange for sharing and managing third-party risk data.
Diligent
A GRC platform providing solutions for audit, risk, compliance, and ESG.
Aravo
An enterprise platform for third-party risk and compliance management.
ProcessUnity
ProcessUnity is a GRC platform that helps businesses manage their risk and compliance programs, including third-party risk management.
Prevalent
Prevalent is a third-party risk management platform that helps businesses manage and monitor the risks associated with their vendors and suppliers.
OneTrust
A platform for privacy, security, and data governance that helps organizations manage trust and comply with regulations.
Netwrix
A software company that provides an IT security and operations platform for auditing, compliance, and data governance.
ZenGRC
A GRC platform that helps organizations manage risk and compliance with greater efficiency and visibility.
LogRhythm
A security intelligence and analytics platform.
IBM QRadar
A security intelligence platform that provides a unified view of an organization's security posture.
Fortinet FortiSIEM
A security information and event management (SIEM) solution that provides unified event correlation and risk management.
Securonix
A next-generation SIEM platform that provides a unified view of an organization's security posture.
AT&T Cybersecurity (AlienVault USM)
A unified security management (USM) platform that provides a comprehensive view of an organization's security posture.
Logz.io
A cloud-native observability platform that provides a unified view of an organization's logs, metrics, and traces.
SailPoint
Identity security for the cloud enterprise.
ForgeRock
A comprehensive identity and access management platform.
SecureAuth
An identity and access management solution for workforce and customer identities.
Qualys Vulnerability Management, Detection and Response (VMDR)
A cloud-based service that provides global visibility into IT assets and their vulnerabilities.
Rapid7 InsightVM
A data-rich resource that prioritizes vulnerabilities based on risk and helps you remediate them faster.
OpenVAS
A full-featured, open-source vulnerability scanner.
ServiceNow GRC
An integrated risk program that transforms inefficient processes across the extended enterprise.
LastPass
A freemium password manager that stores encrypted passwords online.
Sticky Password
A password manager that offers both cloud-based and local Wi-Fi sync options.
Proton Pass
A password manager from the creators of Proton Mail, designed with privacy and security at its core.
LogMeOnce
A password manager and identity management platform that offers a range of passwordless authentication options.
Datadog
A monitoring and security platform for cloud applications.
Splunk
A platform for searching, monitoring, and analyzing machine-generated big data.
Sumo Logic
A cloud-native platform for continuous intelligence.
OneLogin
A cloud-based identity and access management (IAM) provider.
IBM Security Verify
A comprehensive identity and access management (IAM) solution from IBM.
mSecure
A password manager that offers both cloud and local sync options, with a focus on security and a native user experience.
Avira Password Manager
A password manager from the well-known antivirus company Avira, focusing on security and ease of use.
HighBond by Diligent
A GRC platform that helps organizations manage risk, compliance, and audit.
SAI360
An integrated risk and compliance management platform.
Qualys
A cloud-based platform for IT, security, and compliance.
SAI360
A platform for managing risk, compliance, and EHS (Environment, Health, and Safety).
OneTrust
OneTrust is a comprehensive platform for managing privacy, security, and third-party risk.
TrustArc
A provider of privacy management solutions that help businesses comply with global privacy regulations.
Qualys PCI Compliance
An on-demand solution for businesses to validate and achieve compliance with the PCI Data Security Standard.
MetricStream
An integrated risk management and GRC platform for enterprises.
RSA Archer
A GRC platform for managing risk, compliance, and governance.
RSA Archer
A comprehensive GRC platform that helps organizations manage risk and compliance.
MetricStream
A comprehensive GRC platform that helps organizations manage risk, compliance, and audit.
RSA Archer
A comprehensive suite for managing integrated risk management (IRM).
MetricStream
An enterprise platform for Governance, Risk, and Compliance (GRC).
Coupa Risk Assess
Third-party risk and compliance management within the Coupa BSM platform.
MetricStream
MetricStream is a GRC platform that helps businesses manage their risk, compliance, and audit programs.
IBM OpenPages
A highly scalable governance, risk, and compliance (GRC) solution.
Oracle Identity Management
A comprehensive suite of identity and access management solutions from Oracle.
SAP Ariba Supplier Risk
A solution for managing supplier risk within the SAP Ariba network.
True Key
A password manager from McAfee that uses multi-factor authentication to protect your passwords.
Wapiti
An open-source web application vulnerability scanner.
OpenSCAP
A collection of open-source tools for implementing and enforcing security baselines.